LockBit appears hacked, exposing part of its internal conversations
The LockBit ransomware group apparently suffered a breach in its own infrastructure.

News summary
The LockBit ransomware group apparently suffered a breach in its own infrastructure. One of its dark web pages was replaced by a message and a link to data that, according to researchers, appeared to include conversations with victims.
The downfall of a criminal group does not eliminate the risk. The ecosystem evolves and substitutes emerge; corporate defence must focus on resilience, backups and recovery capabilities.
Source: Reuters — 8 May 2025
What happened
In May 2025 the LockBit ransomware group appeared to suffer a breach of its own infrastructure. One of its dark web pages was replaced with a message and a link to a data set that, according to security analysts, appeared to include internal conversations and communications with victims.
The incident was not claimed by authorities nor officially attributed to a law enforcement operation; it was interpreted as a possible action by another actor or a dispute within the criminal ecosystem itself.
What it means for a mid-sized business
The breach or hacking of one specific ransomware group does not eliminate ransomware risk in general. The criminal ecosystem is fragmented and changes quickly: when one group loses infrastructure or reputation, others are ready to take its place.
For a business, the news should not be read as a sign that risk has fallen, but as a reminder that its own defences (recoverable backups, segmentation, response plans) are the only thing it directly controls.
What to review
Resilience elements against ransomware, independent of which group is attacking:
- Recoverable backups, disconnected from the main environment and tested periodically.
- A ransomware incident response plan with roles and decisions defined in advance.
- Network segmentation that limits spread between devices and servers.
- A clear policy on ransom payment, decided before an incident occurs, not during one.
Frequently Asked Questions
- Who hacked LockBit?
- It was not officially attributed to a specific actor; analysts suggested a possible action by another group or an internal dispute, without definitive confirmation.
- Does this mean LockBit has disappeared?
- Not necessarily. Ransomware groups have suffered similar setbacks in the past and reappeared with new infrastructure or a new brand.
- Does this change my company's exposure to ransomware?
- Not directly. Risk depends on your own defences, not on the situation of one specific criminal group.
Concepts mentioned in this article: Backup · Ransomware
If you wish to strengthen the security, continuity and performance of your infrastructure, Seintec can support you from diagnosis through to implementation. Contact us to speak with a specialist.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.